MAS AML / CFT for licensed entities — Timeline and processing benchmarks

Published on: 13 Jul, 2026

MAS AML / CFT for licensed entities — Timeline and processing benchmarks

Raffles Corporate Services works with a panel of corporate and employment law firms; this article is general information, not legal advice.

MAS AML / CFT for licensed entities is the anti-money-laundering and counter-financing-of-terrorism control framework every MAS-regulated financial institution must operate. In practice, a new licensee should budget three to seven months to stand up a compliant AML/CFT programme, from risk assessment through to an independent audit and board sign-off.

What MAS AML / CFT for licensed entities requires

MAS AML / CFT for licensed entities describes the customer due diligence, transaction monitoring, screening and reporting obligations that flow from Singapore’s anti-money-laundering regime. The framework is built on a risk-based approach: a firm must understand its own money-laundering and terrorism-financing risks, then calibrate controls proportionately.

The core building blocks are an enterprise-wide risk assessment, customer due diligence and enhanced due diligence procedures, ongoing transaction monitoring, sanctions and PEP screening, suspicious transaction reporting, and staff training. A named compliance officer and a clear board reporting line anchor the programme.

Firms structuring a regulated fund often run this alongside vehicle set-up; the VCC Act 2018 — Section 107 tax treatment for umbrella VCC — Step-by-step walkthrough shows how the AML track interacts with fund taxation and governance.

Who must comply

All MAS-regulated financial institutions are captured, including capital markets services licensees, licensed and registered fund managers, payment institutions, banks, insurers and financial advisers. Each sector has its own MAS Notice, for example the notices applying to CMS licensees and to payment service providers, but the underlying obligations are consistent.

The intensity of controls scales with risk. A firm serving high-net-worth international clients, dealing in higher-risk jurisdictions, or handling large cross-border flows must apply enhanced measures that a domestically focused adviser may not need.

Statutory basis and MAS notices

The primary statute is the Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act 1992, which criminalises money laundering and underpins the suspicious-transaction-reporting duty. The Terrorism (Suppression of Financing) Act 2002 addresses terrorism financing and imposes reporting obligations where funds are linked to designated persons.

MAS gives sector-specific effect to these statutes through binding Notices issued under Section 27B of the Monetary Authority of Singapore Act 1970. These Notices set out mandatory customer due diligence, record-keeping and screening standards. The regulator publishes its expectations at the Monetary Authority of Singapore, and the statutes themselves are available at Singapore Statutes Online. Suspicious transaction reports are filed with the Suspicious Transaction Reporting Office.

Cost and timeline benchmarks

Standing up an AML/CFT programme typically costs S$25,000 to S$120,000 for a mid-sized licensee, covering the enterprise risk assessment, policy suite, screening tooling and an independent review. Ongoing costs, screening subscriptions, periodic audits and training, run S$15,000 to S$60,000 a year.

Timeline benchmarks: enterprise-wide risk assessment, two to four weeks; policies and procedures, three to five weeks; screening and monitoring tooling configuration, three to eight weeks; independent audit and remediation, three to six weeks. A realistic end-to-end runway is three to seven months.

Step-by-step process

Begin with the enterprise-wide risk assessment, documenting customer, product, geographic and delivery-channel risks. Draft the AML/CFT policy and CDD procedures next. Appoint the compliance officer and set the board reporting cadence. Configure sanctions, PEP and adverse-media screening. Implement transaction monitoring rules calibrated to your risk profile. Train all relevant staff. Finally, commission an independent audit before going live and present the results to the board.

Firms moving from an unlicensed model should review our MAS AML / CFT for licensed entities — Costs and fees breakdown for how AML obligations shift once a licence is granted.

Common mistakes and gotchas

The classic error is a generic, off-the-shelf risk assessment that does not reflect the firm’s actual client base. MAS reviewers spot this immediately. A second is weak ongoing monitoring, onboarding CDD is completed but the customer risk rating is never refreshed. Third, screening false-positive backlogs pile up and genuine hits are missed.

Firms also under-invest in training, leaving front-office staff unable to recognise red flags. Finally, suspicious-transaction reporting is sometimes delayed by internal debate; the duty to report arises on reasonable suspicion, not proof.

Related guides and next steps

AML/CFT sits within a wider onboarding and banking picture. Firms opening operational bank accounts should read our Singapore Pte Ltd company registration for foreigners — Timeline and processing benchmarks, as banks conduct their own due diligence that mirrors many AML requirements. Aligning the two tracks avoids duplicated document requests and speeds account opening.

Documentation and record-keeping

Record-keeping is a statutory obligation, not housekeeping. Firms should retain customer due diligence records, transaction records and the basis for risk ratings for the prescribed period, typically at least five years after the relationship ends or the transaction completes. The enterprise-wide risk assessment, the AML/CFT policy, screening logs and the suspicious-transaction-reporting file must all be readily retrievable.

Auditors and MAS reviewers test whether decisions can be reconstructed: why a customer was rated medium rather than high, why a screening alert was closed, and why or why not a suspicious transaction report was filed. Contemporaneous, reasoned records are the firm’s best defence.

Ongoing monitoring and periodic review

The programme must live after onboarding. Customer risk ratings should be refreshed at trigger events, a change of ownership, unusual activity, adverse media, and on a risk-sensitive periodic cycle. Transaction-monitoring rules should be tuned regularly so that alert volumes remain manageable and genuine risks are not lost in false positives. Sanctions and PEP lists should be updated promptly and re-screened.

An annual independent review, and regular staff training refreshed as typologies evolve, keep the framework current. MAS increasingly expects firms to demonstrate that monitoring produces action, not just alerts, so governance reporting should track how alerts are investigated and closed.

FAQs

How long to build a MAS AML/CFT programme?
Three to seven months. A lower-risk adviser can complete it in about three months; a firm with international HNW clients should plan for six to seven.

Who files suspicious transaction reports?
The firm files STRs with the Suspicious Transaction Reporting Office. The duty arises on reasonable suspicion of criminal proceeds, not on proof.

Do we need a dedicated compliance officer?
Yes. MAS expects a named, suitably senior compliance officer responsible for the AML/CFT programme, with a direct reporting line to the board.

How often must customer risk ratings be reviewed?
On a risk-sensitive basis and at trigger events. Higher-risk customers are reviewed more frequently; ratings should never be set once and left static.

Need help with this? Call, SMS or WhatsApp +65 8501 7133, or email [email protected]. Raffles Corporate Services works with a panel of corporate and employment law firms; this article is general information, not legal advice.